
Senior Security Engineer
Posted Sep 15

Posted Sep 15
This is a fully remote position, open to applicants in United States.
• Define, develop, and execute the strategic technical roadmap for Cloud, Container, and Edge Protection initiatives.
• Oversee and maintain edge and bot protection mechanisms, which include WAF, CDN, and DDoS mitigation strategies.
• Conduct security-centric infrastructure assessments for new product launches and architectural modifications.
• Implement and manage monitoring and alerting systems to identify vulnerabilities and misconfigurations in cloud and container environments.
• Take ownership of container image security, encompassing vulnerability scanning, remediation, and production gating.
• Collaborate with Infrastructure and Engineering teams to integrate security measures into CI/CD pipelines and deployment procedures.
• Partner with Application Security and Engineering to apply controls identified through threat modeling exercises.
• Lead initiatives focused on infrastructure-as-code security and runtime protection.
• Identify gaps in cloud, container, and network security controls and drive solutions to address them.
• Assist in threat modeling, risk assessments, and providing security guidance throughout the development lifecycle.
• Work alongside incident response teams to address cloud-related security incidents.
• Develop tools and automation for proactive remediation and ongoing security validation.
• Monitor and report on DevSecOps KPIs, including mean time to remediate, security control coverage, and trends in vulnerabilities.
• Mentor security engineers and establish technical standards for cloud and container security.
• A minimum of 5 years in DevSecOps, Security Engineering, or related positions.
• Proven experience managing a security program or initiative from inception to execution, including influencing engineering teams beyond your direct reporting structure.
• Proficiency with cloud platforms (GCP, AWS, Azure) and container orchestration technologies (e.g., Kubernetes, ECS).
• Familiarity with cloud and container security tools.
• Strong knowledge of WAFs, bot mitigation techniques, API gateways, and CDN security functionalities.
• Demonstrated experience in conducting secure design and architecture evaluations.
• Competence with Infrastructure as Code (IaC) tools (Terraform, OpenTofu, Helm, etc.) and integrating security scanners into CI/CD pipelines.
• Extensive practical experience with Terraform, OpenTofu, and/or Crossplane.
• Familiarity with CrowdStrike.
• Comprehensive understanding of networking principles (e.g., VPCs, load balancing, firewalls) within a cloud ecosystem.
• Knowledge of database management systems (SQL and NoSQL).
• Relevant certifications are advantageous, including Kubernetes and Cloud Native Security Associate, Certified Kubernetes Security Specialist, Google Professional Cloud Security Engineer, AWS Certified DevOps Engineer, AWS Certified Security - Specialty, and Certified Kubernetes Administrator.
• Must be eligible to work for any employer in the U.S.; employment visa sponsorship is not available.
• Company-subsidized medical, dental, and vision insurance plans.
• 401(k) plan with employer matching.
• Annual performance-based bonus.
• Flexible paid time off (PTO) to promote a healthy work/life balance (2 weeks strongly encouraged!).
• Generous paid leave policies, including 16-week paid parental leave and disability benefits.
• Flexible workplace and modern work schedules focused on achieving results, not just hours worked.
• Company-wide in-person gatherings and team outings.
• Lifestyle enhancement programs.
• Provision of company equipment (with Windows and Mac options available).
• Annual performance evaluations with opportunities for professional growth and career advancement.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.